I have two very different inputs (syslog & exchange message tracking logs) coming from different servers going into different input/filter/output configs in logstash.
Both of these have <13> added to the start of each message when being ingested into logstash and i can't find where it's coming from.
Looking at the stdoutput of the logs, it's in the message when it reaches logstash.
I haven't performed a tcpdump to see if it's in the actual message, that'll be the next step. But does anyone have any clue why this is being added?
I have a few other different inputs that don't get this added.